Kerberos SSO Not Working After Updating to Open JDK 8

Viewed 120

We are using Kerberos to enable SSO in our webapp, it's working fine with Open JDK 7. However with the same configuration when we use Open JDK 8 it fails.

  1. Server : apache-tomcat-8.5.37
  2. JDK : Open JDK 8
  3. Principal Name : HTTP/ats.saifg.tbc.com@SAIFG.TBC.COM

Jass.conf :

com.sun.security.jgss.krb5.initiate {
    com.sun.security.auth.module.Krb5LoginModule required
    doNotPrompt=true
    principal="HTTP/ats.saifg.tbc.com@SAIFG.TBC.COM"
    useKeyTab=true
    keyTab="/home/psleapp0/ats-ui/server/apache-tomcat-8.5.37/conf/SPNEGO/ats.saifg.keytab"
    storeKey=true
    debug=true
    moduleBanner=true;
};

com.sun.security.jgss.krb5.accept {
    com.sun.security.auth.module.Krb5LoginModule required
    doNotPrompt=true
    useKeyTab=true
    storeKey=true
    debug=true
    moduleBanner=true
    principal="HTTP/ats.saifg.tbc.com@SAIFG.TBC.COM"
    keyTab="/home/psleapp0/ats-ui/server/apache-tomcat-8.5.37/conf/SPNEGO/ats.saifg.keytab"
    ;
};
~

Krb5.conf:

[logging]
 default = FILE:/var/log/krb5libs.log
 kdc = FILE:/var/log/krb5kdc.log
 admin_server = FILE:/var/log/kadmind.log

[libdefaults]
 default_realm = SAIFG.TBC.COM
 dns_lookup_realm = false
 dns_lookup_kdc = false
 ticket_lifetime = 24h
 renew_lifetime = 7d
 forwardable = true

[realms]
 SAIFG.TBC.COM = {
  kdc = saifg.tbc.com:88
  admin_server = saifg.tbc.com
 }

[domain_realm]
  .saifg.tbc.com = SAIFG.TBC.COM

SPN and encryption types in keytab :

KVNO Principal
---- --------------------------------------------------------------------------
   0 HTTP/ats.saifg.tbc.com@SAIFG.TBC.COM (des-cbc-crc)
   0 HTTP/ats.saifg.tbc.com@SAIFG.TBC.COM (des-cbc-md5)
   0 HTTP/ats.saifg.tbc.com@SAIFG.TBC.COM (arcfour-hmac)
   0 HTTP/ats.saifg.tbc.com@SAIFG.TBC.COM (aes256-cts-hmac-sha1-96)
   0 HTTP/ats.saifg.tbc.com@SAIFG.TBC.COM (aes128-cts-hmac-sha1-96)

Realm config in Server.xml :

          <Realm
           className="org.apache.catalina.realm.JNDIRealm"
           debug="99"
           connectionURL="ldaps://SAIFG.TBC.COM:3269"
           authentication="simple"
           referrals="follow"
           connectionName="CN=ServiceId,OU=Service Accounts,OU=Accounts,DC=saifg,DC=TBC,DC=com"
           connectionPassword="ServiceIdPassword"
           userSearch="(sAMAccountName={0})"
           userBase="DC=saifg,DC=TBC,DC=com"
           userSubtree="true"
           roleSearch="(member={0})"
           roleName="cn"
           userRoleName="member"
           roleSubtree="true"
           roleBase="DC=saifg,DC=TBC,DC=com" />
        </Realm>

Error :

Debug is  true storeKey true useTicketCache false useKeyTab true doNotPrompt true ticketCache is null isInitiator true KeyTab is /home/psleapp0/ats-ui/server/apache-tomcat-8.5.37/conf/SPNEGO/ats.saifg.keytab refreshKrb5Config is false principal is HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM tryFirstPass is false useFirstPass is false storePass is false clearPass is false
>>> KeyTabInputStream, readName(): SAIFG.tbc.COM
>>> KeyTabInputStream, readName(): HTTP
>>> KeyTabInputStream, readName(): ats.saifg.tbc.com
>>> KeyTab: load() entry length: 63; type: 1
>>> KeyTabInputStream, readName(): SAIFG.tbc.COM
>>> KeyTabInputStream, readName(): HTTP
>>> KeyTabInputStream, readName(): ats.saifg.tbc.com
>>> KeyTab: load() entry length: 63; type: 3
>>> KeyTabInputStream, readName(): SAIFG.tbc.COM
>>> KeyTabInputStream, readName(): HTTP
>>> KeyTabInputStream, readName(): ats.saifg.tbc.com
>>> KeyTab: load() entry length: 71; type: 23
>>> KeyTabInputStream, readName(): SAIFG.tbc.COM
>>> KeyTabInputStream, readName(): HTTP
>>> KeyTabInputStream, readName(): ats.saifg.tbc.com
>>> KeyTab: load() entry length: 87; type: 18
>>> KeyTabInputStream, readName(): SAIFG.tbc.COM
>>> KeyTabInputStream, readName(): HTTP
>>> KeyTabInputStream, readName(): ats.saifg.tbc.com
>>> KeyTab: load() entry length: 71; type: 17
Looking for keys for: HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Java config name: /home/psleapp0/ats-ui/server/apache-tomcat-8.5.37/conf/SPNEGO/krb5.conf
Loaded from Java config
Added key: 17version: 0
Added key: 18version: 0
Added key: 23version: 0
Found unsupported keytype (3) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Found unsupported keytype (1) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
>>> KdcAccessibility: reset
Looking for keys for: HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Added key: 17version: 0
Added key: 18version: 0
Added key: 23version: 0
Found unsupported keytype (3) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Found unsupported keytype (1) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Using builtin default etypes for default_tkt_enctypes
default etypes for default_tkt_enctypes: 18 17 16 23.
>>> KrbAsReq creating message
>>> KrbKdcReq send: kdc=saifg.tbc.com UDP:88, timeout=30000, number of retries =3, #bytes=181
>>> KDCCommunication: kdc=saifg.tbc.com UDP:88, timeout=30000,Attempt =1, #bytes=181
>>> KrbKdcReq send: #bytes read=204
>>>Pre-Authentication Data:
         PA-DATA type = 19
         PA-ETYPE-INFO2 etype = 18, salt = SAIFG.tbc.COMHTTPats.saifg.tbc.com, s2kparams = null
         PA-ETYPE-INFO2 etype = 23, salt = null, s2kparams = null

>>>Pre-Authentication Data:
         PA-DATA type = 2
         PA-ENC-TIMESTAMP
>>>Pre-Authentication Data:
         PA-DATA type = 16

>>>Pre-Authentication Data:
         PA-DATA type = 15

>>> KdcAccessibility: remove saifg.tbc.com:88
>>> KDCRep: init() encoding tag is 126 req type is 11
>>>KRBError:
         sTime is Wed Jul 20 10:35:21 EDT 2022 1658327721000
         suSec is 163481
         error code is 25
         error Message is Additional pre-authentication required
         sname is krbtgt/SAIFG.tbc.COM@SAIFG.tbc.COM
         eData provided.
         msgType is 30
>>>Pre-Authentication Data:
         PA-DATA type = 19
         PA-ETYPE-INFO2 etype = 18, salt = SAIFG.tbc.COMHTTPats.saifg.tbc.com, s2kparams = null
         PA-ETYPE-INFO2 etype = 23, salt = null, s2kparams = null

>>>Pre-Authentication Data:
         PA-DATA type = 2
         PA-ENC-TIMESTAMP
>>>Pre-Authentication Data:
         PA-DATA type = 16

>>>Pre-Authentication Data:
         PA-DATA type = 15

KrbAsReqBuilder: PREAUTH FAILED/REQ, re-send AS-REQ
Using builtin default etypes for default_tkt_enctypes
default etypes for default_tkt_enctypes: 18 17 16 23.
Looking for keys for: HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Added key: 17version: 0
Added key: 18version: 0
Added key: 23version: 0
Found unsupported keytype (3) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Found unsupported keytype (1) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Looking for keys for: HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Added key: 17version: 0
Added key: 18version: 0
Added key: 23version: 0
Found unsupported keytype (3) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Found unsupported keytype (1) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Using builtin default etypes for default_tkt_enctypes
default etypes for default_tkt_enctypes: 18 17 16 23.
>>> EType: sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType
>>> KrbAsReq creating message
>>> KrbKdcReq send: kdc=saifg.tbc.com UDP:88, timeout=30000, number of retries =3, #bytes=270
>>> KDCCommunication: kdc=saifg.tbc.com UDP:88, timeout=30000,Attempt =1, #bytes=270
>>> KrbKdcReq send: #bytes read=98
>>> KrbKdcReq send: kdc=saifg.tbc.com TCP:88, timeout=30000, number of retries =3, #bytes=270
>>> KDCCommunication: kdc=saifg.tbc.com TCP:88, timeout=30000,Attempt =1, #bytes=270
>>>DEBUG: TCPClient reading 1796 bytes
>>> KrbKdcReq send: #bytes read=1796
>>> KdcAccessibility: remove saifg.tbc.com:88
Looking for keys for: HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Added key: 17version: 0
Added key: 18version: 0
Added key: 23version: 0
Found unsupported keytype (3) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Found unsupported keytype (1) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
>>> EType: sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType
>>> KrbAsRep cons in KrbAsReq.getReply HTTP/ats.saifg.tbc.com
principal is HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Will use keytab
Commit Succeeded

Search Subject for SPNEGO ACCEPT cred (<<DEF>>, sun.security.jgss.spnego.SpNegoCredElement)
Search Subject for Kerberos V5 ACCEPT cred (<<DEF>>, sun.security.jgss.krb5.Krb5AcceptCredential)
Found KeyTab /home/psleapp0/ats-ui/server/apache-tomcat-8.5.37/conf/SPNEGO/ats.saifg.keytab for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Found KeyTab /home/psleapp0/ats-ui/server/apache-tomcat-8.5.37/conf/SPNEGO/ats.saifg.keytab for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Found ticket for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM to go to krbtgt/SAIFG.tbc.COM@SAIFG.tbc.COM expiring on Wed Jul 20 20:35:21 EDT 2022
Entered SpNegoContext.acceptSecContext with state=STATE_NEW
SpNegoContext.acceptSecContext: receiving token = a0 82 08 10 30 82 08 0c a0 30 30 2e 06 09 2a 86 48 86 f7 12 01 02 02 06 09 2a 86 48 82 f7 12 01 02 02 06 0a 2b 06 01 04 01 82 37 02 02 1e 06 0a 2b 06 01 04 01 82 37 02 02 0a a2 82 07 d6 04 82 07 d2 60 82 07 ce 06 09 2a 86 48 86 f7 12 01 02 02 01 00 6e 82 07 bd 30 82 07 b9 a0 03 02 01 05 a1 03 02 01 0e a2 07 03 05 00 20 00 00 00 a3 82 05 e5 61 82 05 e1 30 82 05 dd a0 03 02 01 05 a1 0f 1b 0d 53 41 49 46 47 2e 52 42 43 2e 43 4f 4d a2 24 30 22 a0 03 02 01 02 a1 1b 30 19 1b 04 48 54 54 50 1b 11 61 74 73 2e 73 61 69 66 67 2e 72 62 63 2e 63 6f 6d a3 82 05 9d 30 82 05 99 a0 03 02 01 17 a1 03 02 01 05 a2 82 05 8b 04 82 05 87 08 bc 68 25 87 90 72 59 57 8e 8c 6c 7d 71 f0 4f 31 cf 06 87 bb 48 ec 0c e9 e3 96 be 22 58 8d d6 cc 91 ce e1 0e bd e9 5f 37 bf bc b7 9d 56 93 6f 6e 93 01 4c 4c 5e 41 b0 a6 67 2c a0 f5 b0 6e 8e a9 38 1d ad ef c6 d6 6b f7 d2 68 c1 23 51 ad e8 de 78 c0 2c b6 2c 0f d7 75 52 ad c5 dd 62 48 86 c9 3c 2f 87 15 7c 05 cc 3d 55 93 85 db 0e 76 d3 15 9b 75 95 47 f3 78 c3 7b 0a 17 07 ad f6 fa 9f c8 d7 af 5a ae fe 32 ba 58 37 f0 a2 e2 45 9d 2f 1f 5a 1c b0 5c ba 9e ff 2b 7f 52 19 ed 4f 03 55 30 01 bc 8f 48 db c1 73 62 7c c9 39 d2 06 dd 94 f0 dd 65 fd 2d 2c 3b fe 09 9f 2a e5 9c 4c 3f cb 3e 70 23 5c 14 ea 7c d5 50 75 a3 85 5d 0f 5d 07 fe 9e 5d e6 49 5f a7 d9 db 20 56 4c c1 56 93 8d 53 ee 99 7f f5 04 58 f1 ba 3d 28 38 ab bd 6a c5 91 34 d6 20 cb b6 15 e5 a6 85 e5 71 b8 b8 f9 b8 06 a9 c0 27 a2 d6 cd 10 3a 77 e5 9c 65 d0 48 ed da 68 9c 45 1a 37 ba 79 40 b7 0d c7 3b 7d 74 cb 28 d0 19 f8 36 88 47 15 5a fb f5 91 23 73 96 70 d4 57 13 7e a9 c4 c3 c2 16 9e 50 25 33 65 2c f2 2c e4 1d 64 a4 0a 77 19 fa 22 9d 42 a0 d6 6f e1 63 ed 0a 7d 95 37 a9 b6 d3 04 f0 0e 09 04 72 80 12 8b 27 8c 4b 49 d7 70 2a ce 1e 04 e4 99 58 60 02 7c 9b d4 7a 41 41 77 0c 6d 36 f0 d5 0c dd 7c 64 30 a0 12 08 80 e0 c5 bc 8c 1d c8 c0 70 c5 53 09 30 05 4f 40 76 62 93 9f c0 cb 98 d1 4e 7a 0b cd 1d 84 c6 7b 5e 0a f6 c2 49 da 94 84 ee fa 61 da 03 73 63 26 6a 85 90 25 5c 67 34 0d 1b 97 30 ec 9e 14 18 b9 8a 94 31 dc 50 c4 0e b1 09 85 b6 91 3b 5f b8 87 47 92 a5 9b 64 cd a7 0c a5 58 b9 d7 9d c4 57 2d 24 82 a0 ab 37 e8 b2 bc 34 01 6e 1b 0c 1e 84 22 4b 3c 60 f0 84 08 70 e2 65 0a 34 dc 0b 5f fc ae 35 6a 6c fc 88 db 66 d1 25 10 f7 e1 b1 e2 de 0b 66 aa 53 9c a4 e9 2e 48 3b 01 49 92 b7 fe a9 6a 2c 4b d9 1f a0 d3 40 34 51 c1 c6 6d a2 88 31 ae 3e c6 c6 8e e8 3b b6 2b 2d bc 9c 22 14 7c 14 46 f4 78 48 10 be 58 9f a1 52 e2 65 48 2e df 91 65 f9 d9 df a9 8a 67 9e d2 8c 22 71 fc ea f0 9a ce 91 6d 3c bc 79 68 6e fc ef a9 e8 7d cc 42 47 7c e1 48 e9 34 0c b1 b0 7b 3a d8 4f 0b f3 ae 3e 50 2d 87 e4 47 2a 41 b3 06 cb a0 9c b2 4d 08 6f 37 6a e9 0e 25 09 88 46 11 35 cb 15 20 be 67 69 9d 64 86 58 f7 ee 0b 49 08 d2 8b d9 49 16 42 36 d2 99 1b 5f 55 17 e1 f0 38 71 7c 8a 6a 90 14 a9 bf 80 f0 cc c2 da 57 45 f3 00 b7 2c d5 45 f8 0b c9 80 bf 44 eb 71 fe b1 69 89 16 23 d1 51 16 21 1c 0f 35 73 f7 e3 f9 4d 8c 16 29 47 12 25 1f a3 e7 ff 02 02 13 64 dc cc 02 ca f8 a3 b4 7e 1d f2 48 a0 91 46 d9 6f 25 25 76 f7 76 6d 16 3b 49 17 bc 5e 74 3d 8d 45 12 b3 bd 1b e6 c8 f2 95 fa f3 f2 f3 7c 23 0b bb d2 0f 70 d9 4a 77 a0 2a da ed a3 8e 16 a1 e4 68 58 7b fa 47 2c ba 62 c4 22 5c ba 5d 40 ff db 4e 8a 23 0f d3 2b ae ef f8 e1 ae 3a a0 a7 fc 8e c5 1e b1 31 81 4e 69 20 83 df 3f bc 17 4d 60 3b 1d ef 26 6b 06 02 e5 ae 93 cf 07 8a 34 eb d0 34 49 16 51 fe de 0a ce 61 c3 80 6d 9e b4 7a 55 85 4a c9 be cd e5 32 4b a6 24 9d 0a c0 f7 57 e6 3d 09 0e 91 b7 af 6e 23 05 cd 35 76 f5 ff af 26 1b fc be d9 ef 61 06 2a ef da c7 a8 f0 1f 23 3f eb 9a b5 d1 ca 6c 7e 5d f9 d8 00 fe 2a 47 fe f3 f1 c0 80 3c 81 e0 ae 2f 27 7d 0e ce c4 c2 c2 d7 ba 4c 2f 43 7b 79 87 7c d0 00 78 c6 62 67 81 b3 e5 71 ea 88 68 1e db bd fc 09 35 66 bd 1f 39 9d a6 19 27 f8 ff 25 b6 df e4 94 2e 3c a5 93 a0 cb 98 83 85 d8 55 1a 5e 46 e4 70 8f 56 d1 80 76 49 96 84 d5 8e 74 98 6d 15 63 46 23 71 94 98 33 c4 1d 66 48 b3 1c e3 63 fa 52 17 93 49 0c b2 10 1c 8c 48 52 27 3a 21 68 16 a8 d4 6e ad 22 6b 65 c7 4c e4 cb 94 fd 0b 52 f7 9f 37 a9 66 60 4c 92 34 be 80 f3 ea 46 7a 41 a3 d8 bb ba ae 36 e9 d6 3e ff 17 3c f9 b5 73 b0 28 75 7a b4 66 f8 48 f6 77 db 13 0c 24 38 d1 56 02 c4 ac 67 77 38 7c 81 a5 66 ba a3 5b af 31 dd 70 db 47 eb c8 74 42 61 6d b9 15 0c 68 4f 84 99 16 cc c6 98 9f 34 1b 89 5c 03 a7 16 01 23 75 b3 73 e5 63 58 da c9 f9 1b 50 03 8c 46 06 a8 67 2d f3 3a 55 52 82 b3 2c bd 22 14 ac ad 73 23 15 53 b4 12 8b bc d5 2d 0e cf a3 67 d5 ee e1 ff 05 64 9a eb f4 fe 18 97 36 39 e2 31 1c b0 25 3d 52 cd 89 82 a0 3a 6c ac 7b d6 b7 a4 2c b0 6a 69 c8 13 18 cd 37 b3 d8 fc 24 72 9c b4 10 25 9e a7 22 7c 07 96 a2 81 6a 73 e8 22 b6 f5 06 97 f8 d5 2e d4 bd c6 36 82 c1 d4 41 8b b2 2d c3 df e1 33 74 54 d0 67 69 24 e0 98 04 39 fd 4c 96 23 de 50 05 d2 b6 84 2d 01 a7 25 30 e8 ac 98 39 35 3d 5f bc 76 fd a2 f3 01 8e aa c3 0b 30 4d 0f 27 51 65 20 cd 20 39 57 cb 1d 0e b3 f1 2d 7d f7 43 dd ec e1 cc 0c dd 7a 19 c1 e1 16 fa c5 c7 f9 2e d2 7f 0b 7d 7f 17 0f 9a 47 e9 90 4d a4 82 01 b9 30 82 01 b5 a0 03 02 01 17 a2 82 01 ac 04 82 01 a8 d9 88 62 fb 87 8b 9b 40 78 7f ba 69 47 a8 5e 64 2e 46 8d 54 5d b2 77 79 74 7e a1 a9 27 d9 c0 3b 62 7d db 10 71 8c c7 71 bf 08 ef 89 48 94 92 d8 22 5c c9 4c 9b dd 27 46 9c 1e d6 d2 2f 70 7d b9 d5 7e 45 12 c4 4e e0 de 06 a1 eb 5f ac da f0 f4 ef 6f 41 95 95 39 8a 23 d0 fd 21 82 40 86 a6 a5 a7 53 eb f5 f5 fc 21 e7 42 cb 34 75 0d 28 73 6b ac c0 ea 60 92 8e 2b bf 34 1a 1f 88 5d c5 da 01 88 58 ef 35 1b bb 61 3a bc 55 b1 1f 71 61 d3 3c 4c db 47 41 08 48 50 ea 57 bd 6d 28 3a b9 b9 48 78 33 cb 6e a2 a0 57 81 c4 ae c4 83 43 3c a8 d4 d8 12 c3 44 2d 92 bc 8f f0 78 db 24 21 81 6e 61 d7 87 ab bd 27 7d 2b 56 0b b0 a0 8c ed 12 b2 d5 5a 21 d7 b6 76 e3 9f 06 0f e2 58 a9 76 82 99 15 85 01 48 74 50 4d 70 82 88 1e da da e0 2f ab 9b 93 63 51 d2 50 a4 20 16 83 9b ff 23 fb be a7 80 29 6b 72 ec 11 a4 38 5c 79 4e a7 45 be 56 0a bd c3 d5 3a ea 12 53 96 f4 5c 82 c9 09 2d 9e 18 d9 ca 9a 4f d1 f6 b5 1b 01 eb 0b 15 1e 35 d8 7c 49 7e 45 9d 5c 3d 3b 72 b6 28 d3 8f f0 2c 5d 1e cf 3d e7 1a e7 0a 62 6a 05 4a 52 af 3f 70 c8 4c 9e d5 fe 7e de 88 a9 4d 3e 20 23 a4 b9 70 92 6b 72 60 50 15 ca 40 2a 68 96 15 2f bd e7 39 cb 33 01 f3 25 16 0b 51 df f3 ce 76 23 c7 03 b4 40 db c1 09 63 91 cb f9 23 b2 e9 4f da 3a 86 8c 59 77 0c 45 1b 77 9e e2 39 12 e8 b5 0b cf 25 0a 89 60 d8 10 d8 b9 61 d3 c9 ed 14
SpNegoToken NegTokenInit: reading Mechanism Oid = 1.2.840.113554.1.2.2
SpNegoToken NegTokenInit: reading Mechanism Oid = 1.2.840.48018.1.2.2
SpNegoToken NegTokenInit: reading Mechanism Oid = 1.3.6.1.4.1.311.2.2.30
SpNegoToken NegTokenInit: reading Mechanism Oid = 1.3.6.1.4.1.311.2.2.10
SpNegoToken NegTokenInit: reading Mech Token
SpNegoContext.acceptSecContext: received token of type = SPNEGO NegTokenInit
SpNegoContext: negotiated mechanism = 1.2.840.113554.1.2.2
Entered Krb5Context.acceptSecContext with state=STATE_NEW
Looking for keys for: HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Added key: 17version: 0
Added key: 18version: 0
Added key: 23version: 0
Found unsupported keytype (3) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
Found unsupported keytype (1) for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
>>> EType: sun.security.krb5.internal.crypto.ArcFourHmacEType
Using builtin default etypes for permitted_enctypes
default etypes for permitted_enctypes: 18 17 16 23.
>>> EType: sun.security.krb5.internal.crypto.ArcFourHmacEType
MemoryCache: add 1658327721/005043/C2EC8F07E07485B6743690C4BD0E9C3E/hkalauni@SAIOAK.SAIFG.tbc.COM to hkalauni@SAIOAK.SAIFG.tbc.COM|HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM
>>> KrbApReq: authenticate succeed.
Krb5Context setting peerSeqNumber to: 1444206869
>>> EType: sun.security.krb5.internal.crypto.ArcFourHmacEType
Krb5Context setting mySeqNumber to: 18364228
>>> Constrained deleg from GSSCaller{UNKNOWN}
Found ticket for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM to go to krbtgt/SAIFG.tbc.COM@SAIFG.tbc.COM expiring on Wed Jul 20 20:35:21 EDT 2022
SPNEGO Negotiated Mechanism = 1.2.840.113554.1.2.2 Kerberos V5
SpNegoContext.acceptSecContext: mechanism wanted = 1.2.840.113554.1.2.2
SpNegoContext.acceptSecContext: negotiated result = ACCEPT_COMPLETE
SpNegoContext.acceptSecContext: sending token of type = SPNEGO NegTokenTarg
SpNegoToken NegTokenTarg: sending additional token for MS Interop
SpNegoContext.acceptSecContext: sending token = a1 81 eb 30 81 e8 a0 03 0a 01 00 a1 0b 06 09 2a 86 48 86 f7 12 01 02 02 a2 69 04 67 60 65 06 09 2a 86 48 86 f7 12 01 02 02 02 00 6f 56 30 54 a0 03 02 01 05 a1 03 02 01 0f a2 48 30 46 a0 03 02 01 17 a2 3f 04 3d 02 ba fd 53 55 b9 a4 5c c2 63 30 94 aa 57 77 7c 30 03 24 56 ce 19 20 98 21 78 94 5a b0 05 16 37 e2 6c f5 8a 29 7c f5 63 bd 2e 19 b9 8c 4d dd 3d 5e 89 d7 d8 e1 02 bf 77 98 9d ea 21 33 a3 69 04 67 60 65 06 09 2a 86 48 86 f7 12 01 02 02 02 00 6f 56 30 54 a0 03 02 01 05 a1 03 02 01 0f a2 48 30 46 a0 03 02 01 17 a2 3f 04 3d 02 ba fd 53 55 b9 a4 5c c2 63 30 94 aa 57 77 7c 30 03 24 56 ce 19 20 98 21 78 94 5a b0 05 16 37 e2 6c f5 8a 29 7c f5 63 bd 2e 19 b9 8c 4d dd 3d 5e 89 d7 d8 e1 02 bf 77 98 9d ea 21 33
Search Subject for Kerberos V5 INIT cred (<<DEF>>, sun.security.jgss.krb5.Krb5InitCredential)
Found ticket for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM to go to krbtgt/SAIFG.tbc.COM@SAIFG.tbc.COM expiring on Wed Jul 20 20:35:21 EDT 2022
Entered Krb5Context.initSecContext with state=STATE_NEW
Found ticket for HTTP/ats.saifg.tbc.com@SAIFG.tbc.COM to go to krbtgt/SAIFG.tbc.COM@SAIFG.tbc.COM expiring on Wed Jul 20 20:35:21 EDT 2022
Service ticket not found in the subject
>>> Credentials serviceCredsSingle: same realm
Using builtin default etypes for default_tgs_enctypes
default etypes for default_tgs_enctypes: 18 17 16 23.
>>> EType: sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType
>>> CksumType: sun.security.krb5.internal.crypto.HmacSha1Aes256CksumType
>>> EType: sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType
>>> KrbKdcReq send: kdc=saifg.tbc.com TCP:88, timeout=30000, number of retries =3, #bytes=1698
>>> KDCCommunication: kdc=saifg.tbc.com TCP:88, timeout=30000,Attempt =1, #bytes=1698
>>>DEBUG: TCPClient reading 96 bytes
>>> KrbKdcReq send: #bytes read=96
>>> KdcAccessibility: remove saifg.tbc.com:88
>>> KDCRep: init() encoding tag is 126 req type is 13
>>>KRBError:
         sTime is Wed Jul 20 10:35:21 EDT 2022 1658327721000
         suSec is 218484
         error code is 7
         error Message is Server not found in Kerberos database
         sname is ldap/saifg.tbc.com@SAIFG.tbc.COM
         msgType is 30
>>> Credentials serviceCredsSingle: same realm
Using builtin default etypes for default_tgs_enctypes
default etypes for default_tgs_enctypes: 18 17 16 23.
>>> EType: sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType
>>> CksumType: sun.security.krb5.internal.crypto.HmacSha1Aes256CksumType
>>> EType: sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType
>>> KrbKdcReq send: kdc=saifg.tbc.com TCP:88, timeout=30000, number of retries =3, #bytes=1698
>>> KDCCommunication: kdc=saifg.tbc.com TCP:88, timeout=30000,Attempt =1, #bytes=1698
>>>DEBUG: TCPClient reading 96 bytes
>>> KrbKdcReq send: #bytes read=96
>>> KdcAccessibility: remove saifg.tbc.com:88
>>> KDCRep: init() encoding tag is 126 req type is 13
>>>KRBError:
         sTime is Wed Jul 20 10:35:21 EDT 2022 1658327721000
         suSec is 222484
         error code is 7
         error Message is Server not found in Kerberos database
         sname is ldap/saifg.tbc.com@SAIFG.tbc.COM
         msgType is 30
KrbException: Server not found in Kerberos database (7)
        at sun.security.krb5.KrbTgsRep.<init>(KrbTgsRep.java:70)
        at sun.security.krb5.KrbTgsReq.getReply(KrbTgsReq.java:226)
        at sun.security.krb5.KrbTgsReq.sendAndGetCreds(KrbTgsReq.java:237)
        at sun.security.krb5.internal.CredentialsUtil.serviceCredsSingle(CredentialsUtil.java:477)
        at sun.security.krb5.internal.CredentialsUtil.serviceCreds(CredentialsUtil.java:340)
        at sun.security.krb5.internal.CredentialsUtil.serviceCreds(CredentialsUtil.java:314)
        at sun.security.krb5.internal.CredentialsUtil.acquireServiceCreds(CredentialsUtil.java:169)
        at sun.security.krb5.Credentials.acquireServiceCreds(Credentials.java:490)
        at sun.security.jgss.krb5.Krb5Context.initSecContext(Krb5Context.java:695)
        at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:248)
        at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:179)
        at com.sun.security.sasl.gsskerb.GssKrb5Client.evaluateChallenge(GssKrb5Client.java:192)
        at com.sun.jndi.ldap.sasl.LdapSasl.saslBind(LdapSasl.java:125)
        at com.sun.jndi.ldap.LdapClient.authenticate(LdapClient.java:236)
        at com.sun.jndi.ldap.LdapCtx.connect(LdapCtx.java:2897)
        at com.sun.jndi.ldap.LdapCtx.ensureOpen(LdapCtx.java:2799)
        at com.sun.jndi.ldap.LdapCtx.ensureOpen(LdapCtx.java:2772)
        at com.sun.jndi.ldap.LdapCtx.doSearch(LdapCtx.java:1969)
        at com.sun.jndi.ldap.LdapCtx.searchAux(LdapCtx.java:1872)
        at com.sun.jndi.ldap.LdapCtx.c_search(LdapCtx.java:1797)
        at com.sun.jndi.toolkit.ctx.ComponentDirContext.p_search(ComponentDirContext.java:392)
        at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.search(PartialCompositeDirContext.java:358)
        at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.search(PartialCompositeDirContext.java:341)
        at javax.naming.directory.InitialDirContext.search(InitialDirContext.java:267)
        at org.apache.catalina.realm.JNDIRealm.getUserBySearch(JNDIRealm.java:1682)
        at org.apache.catalina.realm.JNDIRealm.getUser(JNDIRealm.java:1518)
        at org.apache.catalina.realm.JNDIRealm.getUser(JNDIRealm.java:1446)
        at org.apache.catalina.realm.JNDIRealm.getPrincipal(JNDIRealm.java:2343)
        at org.apache.catalina.realm.JNDIRealm.getPrincipal(JNDIRealm.java:2269)
        at org.apache.catalina.realm.RealmBase.authenticate(RealmBase.java:509)
        at org.apache.catalina.realm.CombinedRealm.authenticate(CombinedRealm.java:374)
        at org.apache.catalina.authenticator.SpnegoAuthenticator$AuthenticateAction.run(SpnegoAuthenticator.java:345)
        at org.apache.catalina.authenticator.SpnegoAuthenticator$AuthenticateAction.run(SpnegoAuthenticator.java:330)
        at java.security.AccessController.doPrivileged(Native Method)
        at javax.security.auth.Subject.doAs(Subject.java:360)
        at org.apache.catalina.authenticator.SpnegoAuthenticator.doAuthenticate(SpnegoAuthenticator.java:244)
        at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:575)
        at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:140)
        at org.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:650)
        at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:81)
        at org.apache.catalina.authenticator.SingleSignOn.invoke(SingleSignOn.java:240)
        at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:87)
        at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:342)
        at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:800)
        at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:66)
        at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:806)
        at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1498)
        at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
        at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
        at java.lang.Thread.run(Thread.java:750)
Caused by: KrbException: Identifier doesn't match expected value (906)
        at sun.security.krb5.internal.KDCRep.init(KDCRep.java:140)
        at sun.security.krb5.internal.TGSRep.init(TGSRep.java:65)
        at sun.security.krb5.internal.TGSRep.<init>(TGSRep.java:60)
        at sun.security.krb5.KrbTgsRep.<init>(KrbTgsRep.java:55)

0 Answers
Related